Live data from Hacker News

U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service

krebsonsecurity.com

11–20 of 135 posts

Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service

#11

So I began reading and figured, huh, thieves must just stealing be the validation letter USPS would send, and thought, hey, that system which is used in many other places for similar things would be quite vulnerable to that attack, right? But then I got to this bit: > KrebsOnSecurity took the USPS to task last year in part for not using its own unique communications method — the U.S. Mail — to validate and notify res…

You can forward someone else's mail too. Just go to the post office, fill out the form, and drop it in the mailbox. There's no verification, though there is notification at both the old and the new address. Not to mention it's a crime to do that.

Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service

#12

Earlier quoted context omitted.

> It's irrelevant to me whether someone else opens an account with my name If they commit crime in your name, that's your problem no matter what financial system they do it in.

Exactly. It's a self inflicted issue. They claim that "my identity" matters, so it matters. Their decision making affects me through no action of my own. If you sign up at Reddit with the username 'esotericn', I don't care. It doesn't matter. Somehow, if someone signs up for, say, a phone contract in my name and doesn't pay it, it affects some opaque 'credit score' somewhere because an agency couldn't be arsed to do…

So, they shouldn't try to use identifying information to track down people committing crimes?

Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service

#13

So I began reading and figured, huh, thieves must just stealing be the validation letter USPS would send, and thought, hey, that system which is used in many other places for similar things would be quite vulnerable to that attack, right? But then I got to this bit: > KrebsOnSecurity took the USPS to task last year in part for not using its own unique communications method — the U.S. Mail — to validate and notify res…

I signed up earlier this year and the validation required answering several multiple choice questions with data from my credit report such as mortgage, car loan, etc.

I also received a postcard confirming that Informed Delivery had been activated for my postal address.

Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service

#14
post #10

Security Concerns aside. The informed delivery service is great. I've been using it for a little over a year now. They began inserting ads into the Informed Delivery Email. Senders must place some sort of barcode that is then read by the USPS scanner. It's nice to see our postal service trying to close the gap on their (net) loss.

It would be nicer for Congress to not impose capricious retirement funding requirements, artificially making them look unprofitable.

Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service

#15

Earlier quoted context omitted.

Exactly. It's a self inflicted issue. They claim that "my identity" matters, so it matters. Their decision making affects me through no action of my own. If you sign up at Reddit with the username 'esotericn', I don't care. It doesn't matter. Somehow, if someone signs up for, say, a phone contract in my name and doesn't pay it, it affects some opaque 'credit score' somewhere because an agency couldn't be arsed to do…

So, they shouldn't try to use identifying information to track down people committing crimes?

I'm not really sure how to answer this.

Sure.

That's not actually how "identity theft" affects people for the most part.

The case of the police turning up at your door or some sort of court summons because a fake "TazeTSchnitzel" performed fraud is pretty rare.

What actually happens is some opaque credit score thing whereby you just find interacting with the system harder because someone else fucked up.

For example, an agency deciding that because fake "TazeT" managed to get a phone contract and didn't pay it, real "TazeT" must be a layabout and not pay his bills.

Or an account of yours has the password reset because someone sent in a photo of your ID gained from some database leak from a nightclub.

All of this comes about because of inaccurate linking of accounts. There are trivial ways of determining actual linkage, for example if I send money from account A to account B under the same name and it goes uncontested, it's the same identity.

Using stuff like photographs of bits of paper or things sent in the mail as proof is completely asinine. I get mail from half of my street because my postman is underpaid and can't be arsed.

Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service

#16

The fact that "identity theft" is still a thing in 2018 is an indictment on the legacy financial industry. If not for the web of opaque "agencies" that collect and sell data about individuals without affirmative action on behalf of the individual (frankly still surprised this is legal) it would be a complete non-issue. It's irrelevant to me whether someone else opens an account with my name - just as it's irrelevant…

> It's irrelevant to me whether someone else opens an account with my name If they commit crime in your name, that's your problem no matter what financial system they do it in.

In a justice system that actually does what ours pretends to do that isn't my problem at all. I'm innocent until proven guilty, and if other people accept insecure methods of authentification that shouldn't be my problem.

Or put another way: if a burgler spraypaints the words "wongarsu was here" on the walls after relieving a house of its valuables the police may want to hear my side; but it isn't my problem because those words prove nothing.

Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service

#17
post #11

So I began reading and figured, huh, thieves must just stealing be the validation letter USPS would send, and thought, hey, that system which is used in many other places for similar things would be quite vulnerable to that attack, right? But then I got to this bit: > KrebsOnSecurity took the USPS to task last year in part for not using its own unique communications method — the U.S. Mail — to validate and notify res…

You can forward someone else's mail too. Just go to the post office, fill out the form, and drop it in the mailbox. There's no verification, though there is notification at both the old and the new address. Not to mention it's a crime to do that.

Here in Sweden, everyone's address has to be registered with the Tax Agency. In their (securely authenticated by digital ID which can only be obtained using photo ID) online services you can choose to disallow changes of your registered address which are not made digitally to prevent this kind of thing.

Personally I have this turned on, because I'm conscious that every piece of information you'd need to send a fake address change notification for me is either public or easily obtainable with a call to the Tax Agency, which is far from reassuring.

Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service

#18

So I began reading and figured, huh, thieves must just stealing be the validation letter USPS would send, and thought, hey, that system which is used in many other places for similar things would be quite vulnerable to that attack, right? But then I got to this bit: > KrebsOnSecurity took the USPS to task last year in part for not using its own unique communications method — the U.S. Mail — to validate and notify res…

I signed up earlier this year and the validation required answering several multiple choice questions with data from my credit report such as mortgage, car loan, etc. I also received a postcard confirming that Informed Delivery had been activated for my postal address.

I see, so they do some kind of verification. Thanks for your reply!

I guess asking about credit report info is inadequate if people are managing to abuse this. One problem with that kind of thing is it's essentially security by obscurity, it's not deliberately created secret knowledge that can be trusted, it's stuff which happens to not be public and which only you should know, but there's no guarantee and you can't easily change it, right?

Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service

#19

So I began reading and figured, huh, thieves must just stealing be the validation letter USPS would send, and thought, hey, that system which is used in many other places for similar things would be quite vulnerable to that attack, right? But then I got to this bit: > KrebsOnSecurity took the USPS to task last year in part for not using its own unique communications method — the U.S. Mail — to validate and notify res…

Yeah. It's essentially this bad almost everywhere.

You think "surely X" but no. Almost never X. Almost always some lazy Y or nothing at all.

After a couple consulting contracts / vuln disclosures I updated my priors of how competent the government was. I'm actually getting worried now that everything is going cyber-physical and corporations can pull the wool over their eyes. The government is great at offense, but defence is boring. Especially at non-fancy agencies / departments. And the salaries are low.

But it doesn't even matter really. Basically so many things are broken and offense gets better over time while defence gets worse. I'm fighting for regulations, etc. But this stuff is so ill-defined that the government has trouble understanding it.

I have come to blame the universities. The CompSci department should have gone to the Civil or Nuclear Engineering department and said "ok, how do we think about time frames over 100 years?" and built out courses out of that. But other than a handful of rare exceptions, right now most grads come out not understanding the true gravity of their decisions.

The one nice thing is that offense is usually incompetent too. I've been on projects dealing with real crime[0]. The number of people nailed with just getting an IP is lolsy. Most criminals are stupid. I partly want to relay what the smartest 2%ile did just to show how low the bar is, but I fear educating the lower 98%.

[0] Not stupid drug war stuff.

Re: U.S. Secret Service Warns ID Thieves Are Abusing USPS’s Mail Scanning Service

#20

So I began reading and figured, huh, thieves must just stealing be the validation letter USPS would send, and thought, hey, that system which is used in many other places for similar things would be quite vulnerable to that attack, right? But then I got to this bit: > KrebsOnSecurity took the USPS to task last year in part for not using its own unique communications method — the U.S. Mail — to validate and notify res…

I use this service, and when I signed up there was nothing to verify I was who I was. I just put in my address, created an account, and within a day or so could get scans of mail sent to my e-mail.

This is pretty great too. I moved about two months ago, and switched addresses in Informed Delivery. I got a letter saying I switched, but I never put their code into Informed Delivery, and I still get scans of my mail at the new place. I got the scans before the validation letter, so I could easily have stolen that, and no one would know I'm seeing their mail....

*Edit to make things clearer.

I have not validated anything. The letter says I won't get emails unless I put the code in the letter in Informed Delivery. I did not do that ever and I still get the emails.

Post reply on HN